IIBA-CCA Certificate in Cybersecurity Analysis (CCA) Questions and Answers
Analyst B has discovered multiple attempts from unauthorized users to access confidential data. This is most likely?
Other than the Requirements Analysis document, in what project deliverable should Vendor Security Requirements be included?
Organizations who don't quantify this will likely miss opportunities toward achieving strategic goals and objectives:
Where business process diagrams can be used to identify vulnerabilities within solution processes, what tool can be used to identify vulnerabilities within solution technology?
What risk factors should the analyst consider when assessing the Overall Likelihood of a threat?
NIST 800-30 defines cyber risk as a function of the likelihood of a given threat-source exercising a potential vulnerability, and:
The process by which organizations assess the data they hold and the level of protection it should be given based on its risk to loss or harm from disclosure, is known as:
Which of the following activities are part of the business analyst’s role in ensuring compliance with security policies?
